Anvilogic high experimental other

AnyDesk Silent Install [snowflake-crowdstrikefdr_process]

An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. BlackByte ransomware group has been observed performing silent installs of AnyDesk after establishing a foothold. This use case detects silent installation of AnyDesk. - Threat Actor Association: Alloy Taurus/Gallium, Gamaredon (aka. Armageddon, UAC-0010), Muddled Libra, Scattered Spider (aka. 0ktapus, UNC3944), Scatter Swine, UNC2659 - Software Association: Akira, ALPHV/BlackCat, AvosLocker, BianLian, BlackByte, BumbleBee, Clop, Conti, Diavol, Royal

View Source

Detection Logic

select * from crowdstrikefdr_process where event_time > dateadd(hour, -2, sysdate()) and event_platform = 'Win' and regexp_like(process, '.*(anydesk.exe).*(--silent).*', 'i')

Field Validations

Loading…

Comments (0)

Loading comments...